Psychedelic Stealer Weaponizes Compromised Websites

Fake Cloudflare CAPTCHA ClickFix interface leading to Psychedelic Stealer installation

A perilous trap may now await visitors upon seemingly familiar digital terrain: malicious actors have systematically compromised several legitimate Ukrainian websites, covertly embedding a fraudulent Cloudflare verification gateway. This deceptive interface cunningly orchestrates the installation of a novel information-stealing malware dubbed Psychedelic Stealer. On September 24, Arctic Wolf Labs published a comprehensive analysis detailing this ongoing cyberespionage campaign.

Security researchers unearthed this malicious code lurking within the authentic websites of various Ukrainian enterprises, encompassing a medical clinic, automotive and tool retailers, a modeling agency, and a specialized publishing house. The attackers surreptitiously injected an iframe designed to seamlessly load a malicious page they actively control. Consequently, unsuspecting visitors initially arrived at an authentic, trusted resource, only to encounter the fraudulent verification prompt nested seamlessly within.

The Evolution of the ClickFix Technique

This sophisticated lure leverages the notorious ClickFix technique; however, it deviates from the customary PowerShell execution vector, opting instead to weaponize the Windows Installer. Upon clicking the counterfeit CAPTCHA, the deceptive page stealthily copies a malicious msiexec command directly into the user’s clipboard. Subsequently, it instructs the victim to manually open the Windows “Run” dialog (Win+R), paste the newly acquired clipboard contents, and execute the command. For a deep technical dive into this mechanism, you can review the full report on how the Psychedelic Stealer fake ClickFix CAPTCHA targets Ukraine.

Because the web browser inherently refuses to execute this command autonomously, a successful infection absolutely requires active human intervention. If the victim inadvertently follows the deceptive instructions, msiexec immediately downloads a malicious MSI package directly from the attacker’s command-and-control infrastructure. Arctic Wolf documented several mutating installer iterations, with one critical subsequent stage fetching a 64-bit executable designated psychedeliclove.exe. The research team formally christened this malware “Psychedelic Stealer,” deriving the name from a distinctive internal marker embedded deep within the binary code.

Comprehensive Data Theft and Persistence

Upon successful execution, the malware relentlessly hunts for passwords archived within Chromium-based browsers, including Google Chrome, Microsoft Edge, Brave, Opera, and Vivaldi, while simultaneously harvesting sensitive authentication tokens associated with various user accounts. Furthermore, specific modules are ruthlessly targeted at extracting data from cryptocurrency extensions such as MetaMask, Trust Wallet, OKX Wallet, and SafePal. The malware also actively seeks out prominent desktop wallets, including Exodus, Atomic Wallet, Electrum, Bitcoin Core, and Litecoin Core.

Crucially, the capabilities of Psychedelic Stealer extend far beyond mere data exfiltration. The malware forcefully establishes robust persistence by creating a scheduled Windows task. It continuously communicates with its command-and-control server, actively soliciting new operational directives. The operators possess the capability to transmit supplementary executable payloads—including EXE, COM, BAT, CMD, MSI, and PowerShell scripts—meaning this initial infection frequently serves merely as the vanguard for devastating subsequent attacks.

Analyzing the Campaign Infrastructure and Target Demographics

A misconfigured segment of the attacker’s infrastructure inadvertently exposed the campaign’s internal telemetry. The administrative panel recorded 557 unique views originating from 32 distinct nations, resulting in 426 clicks and 79 recorded “complete” events. Tellingly, Ukraine accounted for the overwhelming majority: 446 views, 351 clicks, and 71 completed interface interactions. While these statistics undeniably underscore a laser-focused Ukrainian targeting strategy, they do not accurately reflect the ultimate number of compromised workstations.

Arctic Wolf vehemently emphasizes that the “complete” event is registered the moment the victim clicks the final button on the counterfeit page; it definitively does not prove that the malicious command was executed, the MSI package installed, or that the stealer successfully established communication with the server. Therefore, one must not misinterpret the 79 recorded entries as 79 successful, catastrophic breaches. The ClickFix technique is undergoing rapid, alarming evolution; in September alone, researchers observed variants migrating the deceptive prompt directly into the browser’s address bar.

At present, cybersecurity experts have not definitively linked this campaign to any established Advanced Persistent Threat (APT) group. While analysts discovered Russian-language artifacts embedded within the source code and the administrative panel, Arctic Wolf considers this evidence insufficient for concrete attribution regarding the operators’ true origin. However, the linguistic framing of the instructions, the deliberate selection of compromised websites, and the overwhelming geographical distribution of page views all strongly indicate a primary Ukrainian target audience. Forensic analysis indicates that the foundational infrastructure for this campaign began materializing no later than September 9.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply